NIS2 · Malta

S.L. 460.41 — Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order

What NIS2 documentation costs in Malta — and what the scope depends on

Malta law · S.L. 460.41

Published: · AIPOS OÜ · nis2europe.eu

The short answer: it depends on which documents the law requires from your company

The scope — and therefore the cost — depends on which documents the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41) actually requires from your company. A company that falls outside the Order has no statutory NIS2 documentation duty at all. A company that is an essential entity or an important entity has to cover every area listed in article 19(2), which means a set of documents rather than a single file. The current prices of each individual document and of the full set are shown in the price list on this page.

So the useful question is not "how much" but "which documents does S.L. 460.41 require from us". The three factors below answer it: scope, entity class, and how many of the five core areas your company must document.

Factor one: are you in scope, and in which class?

S.L. 460.41 does not apply to every business in Malta. It applies to the sectors, sub-sectors and types of entities listed in the First Schedule (sectors of high criticality — energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, business-to-business ICT service management, public administration, space) and the Second Schedule (postal and courier services, waste management, chemicals, food, several manufacturing sub-sectors, digital providers, research organisations). Entities established in Malta fall under Maltese jurisdiction, with the exceptions set out in article 23(1).

Within that scope, article 4 sets the class:

If your company is of a type listed in neither Schedule, S.L. 460.41 imposes no documentation duty on it. What remains in practice is commercial: customers who are essential or important entities must take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of their products and cybersecurity practices, including their secure development procedures (article 19(3)). They may therefore ask a supplier for security evidence even though the supplier is not itself in scope.

Factor two: the documentation set is one whole, not a shopping list

For entities in scope, article 19(2) requires measures based on an all-hazards approach, and lists the minimum content. Five core areas drive the documentation:

1. Risk-management policy. Article 19(2)(a) requires policies on risk analysis and information system security. This is where the company's risk picture, its chosen measures and the reasoning behind their proportionality are written down. Article 19(1)(b) ties that proportionality to the entity's exposure to risks, its size, and the likelihood and severity of incidents.

2. Incident handling. Article 19(2)(b) requires incident handling as a measure. It connects to article 20(5), which sets out what an in-scope entity must submit to the national CSIRT: an early warning within twenty-four (24) hours of becoming aware of a significant incident, an incident notification within seventy-two (72) hours, and a final report not later than one (1) month after the incident notification. Documented procedures are what make those steps executable under pressure.

3. Business continuity. Article 19(2)(c) covers business continuity, such as backup management and disaster recovery, and crisis management. Article 19(1)(c)(i) and (iii) place the development, implementation, maintenance and review of business continuity plans, and the maintenance and exercising of an operator security plan, with the appointed security liaison officer.

4. Supply-chain security. Article 19(2)(d) requires supply chain security, including security-related aspects concerning the relationships between the entity and its direct suppliers or service providers. Article 19(3) adds what must be taken into account when deciding which measures are appropriate.

5. Management responsibility and training. Article 18 makes approval and oversight a duty of the management body, and adds training duties — see the next section.

Because supervision can reach the paperwork itself, the set matters. The CIP Department may request information necessary to assess the cybersecurity risk-management measures adopted, including documented cybersecurity policies (article 29(2)(e) for essential entities, article 30(2)(d) for important entities), evidence of implementation of cybersecurity policies (articles 29(2)(g) and 30(2)(f)), and evidence of operator security plans, business continuity plans and where necessary termination plans (articles 29(2)(j) and 30(2)(i)).

Factor three: one document or the full set is a real choice

The risk-management policy is the foundation document. It names the systems and services in question, records the risk analysis and states which measures the company applies — and the other four areas build on it. Incident handling procedures act on the systems and impact levels the policy identifies. The continuity plan restores what the policy treats as critical. The supply-chain section assesses the direct suppliers the policy has mapped. The management approval in article 18(1) attaches to the measures that the policy sets out.

That is why starting with the risk-management policy alone is a coherent step rather than a half-measure: it is the one document the other four cannot be written without. It is equally why it is not the end point. Article 19(2) lists its minimum content as "at least" the enumerated items, and article 19(4) requires that where an entity finds that it does not comply with those measures, it takes corrective measures without undue delay.

Management approval and training under article 18

Documentation in scope is not a purely technical deliverable. Under article 18(1), the CIP Department, or where designated the competent authority, ensures that management bodies of essential and important entities approve the cybersecurity risk-management measures in accordance with article 19 and oversee their implementation. The same sub-article states that the natural persons composing the management bodies may be held liable for infringements of that article, in accordance with articles 31(10)(b) and 33.

Training is stated directly in the Order:

"Members of the management bodies of essential and important entities are required to follow training in order to carry out their tasks."

— S.L. 460.41 article 18(3)

Article 18(4) extends this: essential and important entities shall offer similar training to their employees on a regular basis, so that they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided. Article 19(2)(g) likewise lists basic cyber hygiene practices and cybersecurity training among the minimum measures. A documentation set therefore normally has to record the approval decision and the training arrangements, not only the technical controls.

For the practical details the Order does not spell out — such as the electronic notification and self-registration channel under article 7 — consult the published guidance of the Critical Infrastructure Protection Department (CIP Department) as the official source.

Pricing

VAT

All prices are net (excluding VAT). Invoices are issued by AIPOS OÜ (Estonia).

  • For Estonian clients, Estonian VAT of 24% is added.
  • Business clients in another EU country with a valid VAT number (VIES-verified): reverse charge — 0% on the invoice, you account for VAT in your own country (Art. 196 of the VAT Directive). Without a valid VAT number, Estonian VAT of 24% is added.
  • For clients outside the EU, no Estonian VAT is added (export of services, 0%).

Prices of all services on one page — pricing →

Frequently asked questions

What makes one Maltese company's documentation set larger than another's?

Three things. First, scope: if your type of entity is in neither the First nor the Second Schedule of S.L. 460.41, the Order sets no documentation duty. Second, class under article 4 — essential entity or important entity — which affects how supervision is exercised under articles 29 and 30. Third, how much of article 19(2) your operations actually touch: article 19(1)(b) requires the measures to be proportionate to the entity's exposure to risks, its size, and the likelihood and severity of incidents, so the same minimum list is documented at different depth by different companies.

What is the security liaison officer responsible for under article 19(1)(c)?

Article 19(1)(c) requires the appointment of a security liaison officer with the necessary expertise, who facilitates the development, implementation, maintenance and review of business continuity plans and where necessary termination plans; ensures the entity conducts and maintains appropriate risk assessments; ensures the entity maintains and exercises an operator security plan; and acts as the point of contact between the entity and the CIP Department, or where designated the competent authority. Much of that role is documentary, which is why the plans named there tend to sit in the same set as the risk-management policy.

Does the training duty in article 18 cover employees as well as the management body?

Yes. Article 18(3) requires members of the management bodies to follow training in order to carry out their tasks. Article 18(4) then requires essential and important entities to offer similar training to their employees on a regular basis, so that they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity. Article 19(2)(g) additionally lists basic cyber hygiene practices and cybersecurity training among the minimum measures.

Related topics

These topics are covered in depth on a separate page:

Check your NIS2 compliance

Start the free applicability check

Run the free self-assessment Run the free external security check

The complete NIS2 guide — Malta →

View the free sample package →

Prices of all services on one page — pricing →

This article is general information, not legal advice. Consult a qualified professional for your specific situation.

Content is based on the S.L. 460.41 version in force as of 2026-04-07 (checksum 27a849d7c236).

← Back to home